What is CVE-2026-47702?
CVE-2026-47702 affects TypeBot chatbot builder version 3.16.1, where API tokens are stored as cleartext in the database. This allows attackers with read access to the database to extract bearer credentials used for builder API authentication. Users should upgrade TypeBot and rotate all API tokens immediately.
Azərbaycanca: CVE-2026-47702 TypeBot chatbot qurucusunun 3.16.1 versiyasında aşkar edilib. API tokenləri verilənlər bazasında açıq mətn şəklində saxlanılır ki, bu da verilənlər bazasına oxuma girişi əldə edən hücumçuya həssas etimadnamələri ələ keçirməyə imkan verir. İstifadəçilər TypeBot-u ən son versiyaya yeniləməli və tokenləri fırlatmalıdırlar.
Related CVEs
link basis: same weakness class CWE-522
FAQ2
Which version of TypeBot is affected by CVE-2026-47702?
CVE-2026-47702 affects TypeBot chatbot builder version 3.16.1.
What risk arises from storing API tokens in cleartext in TypeBot?
Attackers with read access to the database can extract sensitive API tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.